Project

General

Profile

Actions

Bug #5261

closed

Not able to capture LAPDm packets and gsm_sms packets

Added by abcd123 over 2 years ago. Updated over 2 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
10/13/2021
Due date:
% Done:

0%

Resolution:
Spec Reference:

Description

I compiled everything(Libosmocre, gnu arm toolchain and osmocombb) in UBUNTU 14.04 (32-bit), running on vmware workstation 16. Everything is cloned from master branches of respective git repositories. I am using Motorola C139.

Outputs

1. Layer1 running ...

root@ubuntu:~/osmocom/osmocom-bb/src/host/osmocon# ./osmocon -p /dev/ttyUSB0 -m c140xor -c ../../target/firmware/board/compal_e86/layer1.highram.bin
got 1 bytes from modem, data looks like: 00 .
got 2 bytes from modem, data looks like: 2e 83 ..
got 4 bytes from modem, data looks like: 1b f6 02 00 ....
got 1 bytes from modem, data looks like: 41 A
got 1 bytes from modem, data looks like: 01 .
got 1 bytes from modem, data looks like: 40 @
Received PROMPT1 from phone, responding with CMD
read_file(chainloader): file_size=32, hdr_len=4, dnload_len=15341
got 1 bytes from modem, data looks like: 1b .
got 1 bytes from modem, data looks like: f6 .
got 1 bytes from modem, data looks like: 02 .
got 1 bytes from modem, data looks like: 00 .
got 1 bytes from modem, data looks like: 41 A
got 1 bytes from modem, data looks like: 02 .
got 1 bytes from modem, data looks like: 43 C
Received PROMPT2 from phone, starting download
handle_write(): 4096 bytes (4096/15341)
handle_write(): 4096 bytes (8192/15341)
handle_write(): 4096 bytes (12288/15341)
handle_write(): 3053 bytes (15341/15341)
handle_write(): finished
got 1 bytes from modem, data looks like: 1b .
got 1 bytes from modem, data looks like: f6 .
got 1 bytes from modem, data looks like: 02 .
got 1 bytes from modem, data looks like: 00 .
got 1 bytes from modem, data looks like: 41 A
got 1 bytes from modem, data looks like: 03 .
got 1 bytes from modem, data looks like: 42 B
Received DOWNLOAD ACK from phone, your code is running now!
Enabled Compal ramloader -> Calypso romloader chainloading mode
Received ident ack from phone, sending parameter sequence
read_file(../../target/firmware/board/compal_e86/layer1.highram.bin): file_size=62980, hdr_len=0, dnload_len=62983
Received parameter ack from phone, starting download
Finished, sent 63 blocks in total
Received branch ack, your code is running now!
fb_td014_init: initializing LCD.
Looking for TIFFS (TI Flash File System) header at 0x370000, 5 sectors of 0x10000 bytes
Found TIFFS active index block at 0x3a0000
Found TIFFS root inode at #d1

OsmocomBB Layer 1 (revision osmocon_v0.0.0-2615-g9821955-modified) ======================================================================
Device ID code: 0xb4fb
Device Version code: 0x0000
ARM ID code: 0xfff3
cDSP ID code: 0x0128
Die ID code: f1562414ab039771 ======================================================================
REG_DPLL=0x2413
CNTL_ARM_CLK=0xf0a1
CNTL_CLK=0xff91
CNTL_RST=0xfff3
CNTL_ARM_DIV=0xfff9 ======================================================================
Power up simcard:
Analyzing factory records sector at 0x3fc000
Found 900 MHz band calibration record at 0x3fc100, applying
Found 1800 MHz band calibration record at 0x3fc19c, applying
Assert DSP into Reset
Releasing DSP from Reset
Setting some dsp_api.ndb values
Setting API NDB parameters
DSP Download Status: 0x0001
DSP API Version: 0x0000 0x0000
Finishing download phase
DSP Download Status: 0x0002
DSP API Version: 0x3606 0x0000
LOST 7376!

2. ccch_scan running ...

root@ubuntu:~/osmocom/osmocom-bb/src/host/layer23/src/misc# ./ccch_scan -a 110 -i 127.0.0.1
Copyright (C) 2010 Harald Welte <>
Contributions by Holger Hans Peter Freyther

License GPLv2+: GNU GPL version 2 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

<0001> app_ccch_scan.c:140 BCCH message (type=0x1c): SYSTEM INFORMATION TYPE 4
<0001> app_ccch_scan.c:140 BCCH message (type=0x00): SYSTEM INFORMATION TYPE 13
<0001> app_ccch_scan.c:140 BCCH message (type=0x07): SYSTEM INFORMATION TYPE 2quater
<0001> app_ccch_scan.c:140 BCCH message (type=0x1b): SYSTEM INFORMATION TYPE 3
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(1310270831)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3812312586)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(1580380651)
<0001> app_ccch_scan.c:140 BCCH message (type=0x1c): SYSTEM INFORMATION TYPE 4
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(1227455787)
<0001> app_ccch_scan.c:140 BCCH message (type=0x19): SYSTEM INFORMATION TYPE 1
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(422551635)
<0001> app_ccch_scan.c:140 BCCH message (type=0x1a): SYSTEM INFORMATION TYPE 2
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(841676435)
<0001> app_ccch_scan.c:140 BCCH message (type=0x1b): SYSTEM INFORMATION TYPE 3
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(724375819)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(2955370625)
<0001> app_ccch_scan.c:140 BCCH message (type=0x1c): SYSTEM INFORMATION TYPE 4
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(2232371765)
<0001> app_ccch_scan.c:140 BCCH message (type=0x00): SYSTEM INFORMATION TYPE 13
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(271219115)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(925933787)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3963307436)
<0001> app_ccch_scan.c:140 BCCH message (type=0x07): SYSTEM INFORMATION TYPE 2quater
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x1b): SYSTEM INFORMATION TYPE 3
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(842190187)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(4013653124)
<0001> app_ccch_scan.c:140 BCCH message (type=0x1c): SYSTEM INFORMATION TYPE 4
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3020627541)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3896200673)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3241889820)
<0001> app_ccch_scan.c:140 BCCH message (type=0x19): SYSTEM INFORMATION TYPE 1
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x1a): SYSTEM INFORMATION TYPE 2
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x1b): SYSTEM INFORMATION TYPE 3
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x1c): SYSTEM INFORMATION TYPE 4
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(607123395)
<0001> app_ccch_scan.c:140 BCCH message (type=0x00): SYSTEM INFORMATION TYPE 13
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x07): SYSTEM INFORMATION TYPE 2quater
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3661330532)
<0001> app_ccch_scan.c:140 BCCH message (type=0x1b): SYSTEM INFORMATION TYPE 3
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x1c): SYSTEM INFORMATION TYPE 4
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:140 BCCH message (type=0x19): SYSTEM INFORMATION TYPE 1
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:425 PCH pdisc (NCSS) != RR
<0001> app_ccch_scan.c:449 Unknown PCH/AGCH message (type 0x2b): 01 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(590502099)
<0001> app_ccch_scan.c:282 Paging1: Normal paging chan any to tmsi M(3711654172)

I am attaching pcapng file. There is no LAPdm packets and no gsm_sms packets (downlink). But when I use RTL-SDR I get both LAPdm packets as well as gsm_sms packets (downlink).
Please help!!


Files

my-capture.pcapng my-capture.pcapng 70.8 KB Wireshark pcapng abcd123, 10/13/2021 03:38 PM
Actions #1

Updated by fixeria over 2 years ago

  • Category deleted (OsmocomBB Firmware)
  • Status changed from New to Rejected
  • Priority changed from High to Normal
  • Target version deleted (GAPK (GSM Audio Pocket Knife) back-end intergation)
  • Resolution deleted (wontfix)

As the name implies, ccch_scan operates on CCCH (Common Control Channels), while you're talking about DCCH (Dedicated Control Channels). However, there is a hacked version of ccch_scan by Sylvain Munaut in his branch (https://git.osmocom.org/osmocom-bb/log/?h=sylvain/burst_ind) - I guess this is what you're looking for. It switches to DCCHs from RR Immediate Assignment messages.

There is no LAPdm packets and no gsm_sms packets (downlink). But when I use RTL-SDR I get both LAPdm packets as well as gsm_sms packets (downlink).

This works because the flow-graph of grgsm_livemon contains an additional chain for decoding all sub-channels of SDCCH/8 on TS1.

Actions

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 48.8 MB)